CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
Summary
CISA has confirmed that ransomware gangs are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 devices. One of these flaws is a critical server-side request forgery (SSRF) vulnerability.
IFF Assessment
The exploitation of critical vulnerabilities by ransomware gangs represents a direct threat to organizations, enabling malicious actors to compromise systems and deploy ransomware.
Severity
The article mentions a 'maximum-severity server-side request forgery (SSRF) flaw' in SonicWall SMA1000, implying a high impact and exploitability, characteristic of a CVSS score of 10.0.
Defender Context
This alert signifies an active threat from ransomware actors leveraging known vulnerabilities in SonicWall SMA1000 devices. Defenders must prioritize patching these identified flaws and monitor their networks for any signs of exploitation.